.png)
On September 27, 2026, Citrix disclosed eight vulnerabilities in NetScaler, the gateway in front of remote access and business applications at thousands of companies. Two of them, CVE-2026-88771 and CVE-2026-88772, have already been exploited before anyone outside the attackers knew they existed. The same day, CISA added both to its Known Exploited Vulnerabilities catalog and gave federal agencies until Wednesday to patch. For each of those organizations, the fix meant taking remote access and every application that routes through the gateway offline this week. The faster you can restore the business, the faster you can afford to patch.
The latest from Gambit: research, insights, and live sessions

